Last updated 5 September 2026
Privacy policy
Runbound was built so that the personal things stay personal. Your heart rate, your cadence, your route and your run history are read on your phone and your watch and they stay there. This page says exactly what does leave, why, and what you can make us do about it.
Who is responsible
Runbound is made by Cre8-it B.V., a company registered in the Netherlands. The data controller is Cre8-it B.V., identified by the trade register number below.
| Controller | Cre8-it B.V. |
| Address | Baron van Nagellstraat 136, 3771 LL Barneveld, Netherlands |
| KvK | 42147119 |
| VAT | NL869923651B01 |
| hello@runbound.app |
There is no data protection officer. The app does not process personal data on a scale that requires one, and for anything on this page you are writing to the people who built the app.
Health data never reaches us
Runbound reads workouts, running distance, heart rate, step count and workout routes from Apple Health, and writes your finished runs back to it. All of that happens on your device. None of it is transmitted to us, and there is no server that could hold it: Runbound has no account, no login and no cloud copy of your plan or your runs.
Health measurements are excluded from everything the app sends, whatever it is sent for: no distance, no duration, no pace, no heart rate, no cadence, ever.
Apple Health access is required for guided runs. Without it the watch cannot read pace, distance, cadence or heart rate, so it cannot guide a run or save one. Planning, your schedule and route planning still work, but the guided run is the heart of the app. You grant and withdraw this access in Apple’s own Health permission screens, not in ours.
What does leave your device
Planning a route
When you ask for a round-trip route, the app sends the coordinates you are starting from to our routing service, which is hosted in the European Union. That is the only way to draw a route that comes back to where you started.
You can also set that starting point yourself, by placing it on the map. A start you place needs no location access at all, and it is the same two numbers either way. If you drop a pin somewhere you want to run past, that point is sent with it, for the same reason and on the same terms.
Nothing travels with those coordinates: no name, no account, no plan, no run history, no identifier of any kind. We do not store them. For about two minutes our routing service keeps the answer it worked out, so that asking for several variations of the same route costs one calculation instead of a dozen; that copy is keyed by the points you asked about and is discarded on its own.
When it happens. Normally when you open Routes. Runbound also offers to get your next run’s routes ready in advance, so the map is drawn instead of loading, and with that on the same starting point is sent a little earlier: when the app expects you to want a route rather than at the moment you ask. It never switches on GPS to do it, and it uses only a start it already knows. The switch is Get routes ready in advance, under You, and turning it off means nothing is sent until you open Routes.
- Purpose: drawing a route you asked for, or are about to.
- Lawful basis: performance of the contract, Article 6(1)(b) GDPR, for a route you asked for. For getting them ready in advance, legitimate interest, Article 6(1)(f): the same request, sent early so it is waiting for you. One switch turns it off.
- Kept: not stored.
Anonymous usage and crash data
Runbound sends product analytics and crash reports to PostHog, on their European servers. This is how we learn which parts of the app help people run, and how we find out that the app crashed for someone instead of waiting for them to tell us.
What is sent:
- That things happened: the app opened, a plan was created, a run was completed, a screen was viewed, a paywall was seen, a route was planned.
- Plan shape: goal type, goal value, timeline, rhythm, strain rating.
- Crashes: the type of crash and the stack trace showing where in our code it happened.
- Technical context that PostHog’s software attaches automatically: app version, device model, operating system version, language, time zone, screen size and whether you were on wifi.
- A random identifier generated on your device the first time the app runs, so that two events from the same install can be recognised as such. It is not linked to your name, your email or any account, because there is none. Delete the app and it is gone for good.
- An approximate country, which PostHog derives from the internet address your device connects from. We never send a location; a country inferred from a network connection is a different thing, and we would rather name it here than pretend it does not happen.
What is never sent: anything measured about your body or your movement. No heart rate, no cadence, no distance, no duration, no pace, no coordinates, no route. Nothing at all from workouts imported from Apple Health.
- Purpose: understanding which features help, and fixing crashes.
- Lawful basis: legitimate interests, Article 6(1)(f) GDPR. Our interest is in a working, improving app; the effect on you is slight because the data says nothing about your health or where you are; and you can switch it off.
- How to switch it off: open You, scroll to Privacy, turn off Share anonymous usage data. Off means off: the analytics software is not started at all, so nothing is collected, queued or sent, including crash reports.
- Kept: 12 months, then deleted by PostHog.
- Processor: PostHog, under a signed data processing agreement. Their servers for this project are in the European Union. Where any transfer outside the EEA occurs, it is covered by the European Commission’s standard contractual clauses.
Preventing abuse
Checking whether this device still has free runs left involves one anonymous signal from Apple. It means something to Apple and to nobody else: it carries no name, no location and no health data, and we store nothing.
- Purpose: preventing abuse of the free allowance.
- Lawful basis: legitimate interests, Article 6(1)(f).
- Kept: nothing on our side.
Paying
Apple sells the subscription, not us. We never see your card, your billing address or your Apple Account. Apple tells the app whether a valid subscription exists, and that is all we learn. Refunds, cancellations and billing questions go through Apple.
This website
runbound.app uses PostHog for analytics, in the EU, and it loads only if you press Allow in the banner. Decline and no analytics script runs and no analytics cookie is set. Your choice is stored in your own browser.
Serving the site means our hosting provider handles the traffic your browser makes, including your IP address, as every web host must.
Who processes data for us
| Who | What they get | Where |
|---|---|---|
| PostHog | Usage events and crash reports | European Union |
| Cloudflare | Website and service traffic, including IP addresses | Global network |
| Microsoft | Hosting for our routing service, so route coordinates pass through it while a route is calculated | European Union |
| Apple | The anti-abuse signal above, subscription status, and your Health data, which stays on your device | Apple’s own terms apply |
Apple is not our processor. Where Apple handles your data for Health, for the signal above or for the App Store, Apple decides how, under Apple’s privacy policy.
How long we keep things
| What | How long |
|---|---|
| Your plan, your runs, your route history | On your device, until you delete the app |
| Route coordinates | Not stored |
| The anti-abuse signal | Not stored by us |
| Usage events and crash reports | 12 months, then deleted |
| An email you send us | As long as it takes to answer you, and a reasonable while after |
How it is protected
Most of the risk is removed before it starts, by design rather than by promise: there is no account to break into, no password to steal and no database of anybody’s runs, because your plan and your runs never leave your phone and your watch.
What does leave travels over encrypted connections to the processors named above, each under a written data processing agreement, and access to our own systems is limited to the people who build the app.
No system is perfect and we will not pretend otherwise. If a breach ever affects personal data, we report it to the Dutch supervisory authority within 72 hours and tell you directly where the law requires it.
Leaving Europe
The processing described here happens in the European Union, apart from website traffic, which reaches you through a global network. Where any personal data is processed outside the European Economic Area, that transfer is covered by the European Commission’s standard contractual clauses.
Your rights
You can ask us to give you a copy of your personal data, correct it, delete it, restrict what we do with it, hand it to someone else in a portable form, or object to us processing it at all. Where we rely on legitimate interests, you can object and we will stop unless we can show compelling grounds that override your rights, which for usage analytics we would not attempt.
Write to hello@runbound.app. We answer within one month.
There is an honest limit worth stating: the analytics data is not linked to you, so we usually cannot find “your” events to hand over or delete. If you want them gone, turning the switch off in You stops new ones, and the old ones expire within 12 months. We would rather say this plainly than pretend to a power we do not have.
You also have the right to complain to a data protection authority: the one where you live, the one where you work, or the one where you think something went wrong. Ours is the Dutch Autoriteit Persoonsgegevens.
Children
Runbound is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has been using it, write to us and we will help.
Automated decisions
Runbound builds a training plan and rates the strain it puts on you. That is a suggestion you can change or ignore, not a decision with legal or similarly significant effects, and no profiling in the sense of Article 22 takes place.
Changes
If this policy changes in a way that matters, the app will tell you before it takes effect. The date at the top of this page always reflects the current version.
← Back to Runbound